Impact
A topology submitted to Apache Storm Nimbus can contain two lists of blobstore keys – dependency_jars and dependency_artifacts. Nimbus does not validate the keys in those lists. During cleanup it deletes checks; an attacker can therefore delete a blob belonging to another topology. Separately, when Nimbus becomes leader it verifies that all dependency keys of active topologies exist, surrendering leadership and requeuing when a key is missing. A single missing key on one active topology can cause all Nimbus instances to lose leadership repeatedly, preventing scheduling, cleanup, or new submissions. These weaknesses are both input validation (CWE‑20) and authorization bypass through user‑controlled keys (CWE‑639), and together they allow cross‑tenant data deletion and denial of service.
Affected Systems
Apache Software Foundation’s Apache Storm Nimbus component. No specific product versions are enumerated, but the official fix is to upgrade to Nimbus 3.1.0 or later, which enforces validation of dependency keys on submission.
Risk and Exploitability
The risk is high because an attacker who can submit a topology can delete another topology’s data and can cripple the cluster until leadership is restored. The attack vector is the topology submission interface; no external network primitives are required beyond the normal Nimbus client. Exploitation requires no privileged access to the cluster beyond normal topology submission rights. The CVSS score is 9.1, EPSS score is < 1% (approximately 0.0042), and the vulnerability is not listed in the CISA KEV catalog, but the lack of validation makes it straightforward for a submitter to trigger the impact.
OpenCVE Enrichment